summaryrefslogtreecommitdiff
AgeCommit message (Collapse)AuthorFilesLines
2011-12-13Update p5-Proc-Simple to 1.30.hiramatsu2-7/+6
Changes from previous: ---------------------- From 1.29: [RT 69782] Zefram reported race condition in t/sh-c.t, fixed by adding polling loop. Found that kill(-sig, pid) sometimes fails with 'process id not found' although a previous kill(0, pid) succeeded. This is a race condition condition caused by a newly forked child that hasn't called setsid() yet and therefore its new process group id doesn't exist yet, although the child responds to poll(). kill() now deals with this case. From 1.28: [RT 69103] Typo fix by Salvatore Bonaccorso Added support for processes called via 'sh -c' by system() (see "Shell Processes" note in the manpage). From 1.27: [RT 62802] Pod fix by Salvatore Bonaccorso [RT 63833] Applied patch to stop reaping PIDs of no longer existing processes (submitted by perlbotics). Added licensizer [RT 63833] (second part) Added cleanup() class method to delete timing data of reaped processes, avoiding infinite memory growth on long-running processes From 1.26: [RT 62285] Pod fix for redirect_output() Fixed github link
2011-12-13Update p5-Catalyst-Authentication-Store-DBIx-Class to 0.1503.hiramatsu2-7/+6
Changes from previous: ---------------------- 0.1503 2011-12-08 * Change docs to show $c->config('Plugin::Authentication' => {... rather than $c->config->{authentication}. The new key, and method rather than hash access style are both preferred and recommended. 0.1502 2011-08-24 * Switch repository to git (fREW Schmidt) 0.1501 2011-06-17 * If use_userdata_from_session isn't set, then don't store more fields than we need in the session -- only the fields we need to load the object from the DB again. 0.1500 2010-11-16 * Allow specifying a fully loaded DBIC result in addition to resultsets of which only the first row is considered. 0.1401 2010-11-16 * Fix call to ->load which was not passing $c
2011-12-13Update p5-Image-ExifTool to recent production release 8.65.hiramatsu2-7/+6
Changes from previous: ---------------------- Sept. 24, 2011 - Version 8.65 (production release) - Added a few new CanonModelID's - Added a new Sony/Minolta LensType - Added a new Canon LensType (thanks Klaus Reinfeld) - Added a number of new Olympus ArtFilter/MagicFilter values - Included new .args files in distribution: exif2iptc.args and iptc2exif.args - Enhanced writing of date/time tags to recognize "now" for the current time - Improved decoding of H264 Gain - Minor improvement to -htmlDump for some invalid IFD entries - Allow PostScript date/time tags to be written without the -n option - Allow NikonCapture:ExposureAdj2 to be written without the -n option - Fixed problem introduced in version 8.62 where DateTimeOriginal in IFD0 of NEF images was no longer updated when shifting times - Fixed problem where keywords could be duplicated when exporting to XMP while using the MWG module - Fixed problem reading PDF images with extra whitespace before xref table - Fixed format problem in CSV output for filenames containing a comma or quote - Fixed problem reading concatenated AVI videos Sept. 10, 2011 - Version 8.64 - Added 2 new ACDSee XMP tags (thanks Hannes Leubbers) - Added a new Sony FileFormat value - Added a new CanonModelID - Added a few new Pentax DigitalFilter and ImageTone values - Enhanced -execute option to allow a command ID number to be added - Enhanced -csv and -json import features to also key on canonical SourceFile path (requires Cwd module) - Improved Composite LensID logic for some Sony cameras - Fixed misleading error message when using -if option on file that doesn't exist - Fixed problems decoding a number of inconsistent tags in the Sigma SD1 maker notes Aug. 27, 2011 - Version 8.63 - Added support for a number of new Open Document file extensions - Added a few new CanonModelID and SonyModelID values - Added a new Ricoh GXR LensID - Added a new Sony/Minolta LensType (thanks Mladen Sever) - Added patch to read the improperly formatted DateTimeOriginal in AVI videos written by the Kodak Easyshare Sport camera - API Changes: - Added QuickTimeUTC option Aug. 21, 2011 - Version 8.62 - "JPEG2000 Update" - Added read support for JPEG2000 codestream format (J2C) - Added a few new Nikon LensID's (thanks Robert Rottmerhusen) - Added a few new Pentax LensType's - Added a few new Sony/Minolta LensType's (thanks Wolfram for 2 of these) - Added two new Sony Teleconverter values (thanks Wolfram) - Decode a few more JPEG2000 UUID's written by Adobe JPEG2000 plugin - Decode additional JPEG2000 ColorSpecification information - Recognize a few more JPEG2000 file extensions - Updated some CanonModelID's - Tolerate extra comma at end of line in imported -csv files - Changed name of Kodak Type9 SerialNumber tag to UnknownNumber - Fixed bug which in rare situations could result in an erroneous "IFD pointer references previous IFD" warning - Fixed another memory leak when writing and removed circular references from ExifTool object to prevent future bugs like this - Fixed problem in Windows where values in the -X (XML) output containing CR+LF were converted to CR+CR+LF - Fixed superfluous warning which could occur when using += to decrement a numerical tag - Fixed an incorrectly spelt Pentax city name (thanks John Francis) July 16, 2011 - Version 8.61 - Added the ability to increment/decrement tags with numerical values using += - Added support for Extensis Portfolio XMP tags plus a number of non-standard and/or undocumented XMP-xmp and XMP-xmpMM tags - Added read support for Microsoft Compiled HTML (CHM) format - Added read support for Ogg Video (OGV) files - Added new LensType values for Pentax (thanks Heike Herrmann), Sony/Minolta (thanks Fabio Suprani and Florian Knorn), Nikon (thanks Jens Kriese), Olympus and Sigma cameras - Added a new QuickTime VendorID - Recognize DEX (Dalvik Executable) files - Identify Windows 64-bit EXE/DLL files and relax EXE validation - Validate date/time values when reading NMEA GPS log files - Changed decoding of CFAPattern to return a string of numbers with -n option - Extract all unknown makernote blocks as undef, regardless of actual format - Improved print conversion of Pentax ShakeReduction - Fixed problem processing some Ogg files with multiple streams - Fixed incorrect namespace URI for stArea (used by MWG 2.0 regions) - Fixed problem with spaces in -geotag path when using wildcards - Fixed problem writing PDF:Keywords list items individually if they contain special characters - API Changes: - Enhanced SetNewValue() to allow increment/decrement of numerical tags
2011-12-13Update p5-libs-abs to 0.92.hiramatsu2-7/+6
Change from previous: --------------------- 0.92 2010-11-15 Added "WHY" section into POD
2011-12-13Update p5-Test-Requires to 0.06.hiramatsu2-7/+6
Change from previous: --------------------- 0.06 - support Perl 5.6.0 or later. Because Mouse need to support it. (gfx)
2011-12-13Updated databases/mysql55-{client,server} to 5.5.19adam1-1/+3
2011-12-13Changes 5.5.19:adam3-7/+20
* Performance of metadata locking operations on Windows XP systems was improved by instituting a cache for metadata lock objects. This permits the server to avoid expensive operations for creation and destruction of synchronization objects on XP. A new system variable, metadata_locks_cache_size, permits control over the size of the cache. The default size is 1024. * Replication: Previously, replication slaves could connect to the master server through master accounts that use nonnative authentication, except Windows native authentication. This is now also true for Windows native authentication. Bugs Fixed: * InnoDB Storage Engine: An internal deadlock could occur within InnoDB, on a server doing a substantial amount of change buffering for DML operations, particularly DELETE statements. * Rounding DBL_MAX returned DBL_MAX, not 'inf'. * mysql_upgrade did not upgrade the system tables or create the mysql_upgrade_info file when run with the --write-binlog or --skip-write-binlog option. * If a plugin was uninstalled, thread local variables for plugin variables of string type with wth PLUGIN_VAR_MEMALLOC flag were not freed. * Deadlock could occur when these four things happened at the same time: 1) An old dump thread was waiting for the binary log to grow. 2) The slave server that replicates from the old dump thread tried to reconnect. During reconnection, the new dump thread tried to kill the old dump thread. 3) A KILL statement tried to kill the old dump thread. 4) An INSERT statement caused a binary log rotation.
2011-12-13Upstream changelog:spz3-8/+9
Tomcat 6.0.35 (jfclere) +++++++++++++++++++++++ Catalina -------- fix Fix regression in decoding of parameters that contain spaces. Patch by Willem Fibbe. (kkolinko) Tomcat 6.0.34 (jfclere) not released ++++++++++++++++++++++++++++++++++++ Catalina -------- fix 51550: Display an error page rather than an empty response for an IllegalStateException caused by too many active sessions. (markt) add 51640: Improve the memory leak prevention for leaks triggered by java.sql.DriverManager. (markt/kkolinko) fix 51688: JreMemoryLeakPreventionListener now protects against AWT thread creation. (schultz) fix 51758: The digester (used for processing XML files) used the logger name org.apache.commons.digester.Digester rather than the expected org.apache.tomcat.util.digester.Digester. The digester has been changed to use the expected logger name. (kkolinko) add 51862: Added a classesToInitialize attribute to JreMemoryLeakPreventionListener to allow pre-loading of configurable classes to avoid some classloader leaks. (slaurent) fix 51872: Ensure that the access log always uses the correct value for the remote IP address associated with the request and that requests with multiple errors do not result in multiple entries in the access log. (markt) add Allow to overwrite the check for distributability of session attributes by session implementations. (rjung) add Provide the log format "OneLineFormatter" for JULI that provides the same information as the default plus thread name but on a single line. (markt/rjung) fix Ensure the the memory leak protection for the HttpClient keep-alive always operates even if the thread has already stopped. (markt) fix 51940: Do not limit saving of request bodies during FORM authentication to POST requests since any HTTP method may include a request body. Based on a patch by Nicholas Sushkin. (kkolinko) fix 52091: Address performance issues related to lock contention in StandardWrapper. Based on patch provided by Taiki Sugawara. (kkolinko) update In GenericPrincipal, SerializablePrincipal: Do not sort lists of roles that have only one element. (kkolinko) add Make configuration issue for CsrfPreventionFilter result in the failure of the filter rather than just a warning message. (kkolinko) fix Ensure changes to the configuration of RemoteAddrValve and RemoteHostValve via JMX are thread-safe. (kkolinko) add Make configuration issue for RemoteAddrValve and RemoteHostValve result in the failure of the valve rather than just a warning message. (kkolinko) update In RequestFilterValve (RemoteAddrValve, RemoteHostValve): refactor value matching logic into separate method and expose this new method isAllowed through JMX. (kkolinko) add Improve performance of parameter processing for GET and POST requests. Also add an option to limit the maximum number of parameters processed per request. This defaults to 10000. Excessive parameters are ignored. Note that FailedRequestFilter can be used to reject the request if some parameters were ignored. (markt/kkolinko) add New filter FailedRequestFilter that will reject a request if there were errors during HTTP parameter parsing. (kkolinko) Coyote ------ fix 50394: Return -1 from read operation instead of throwing an exception when encountering an EOF with the HTTP APR connector. (kkolinko) fix 51698: Fix CVE-2011-3190. Prevent AJP message injection. (markt) fix Detect incomplete AJP messages and reject the associated request if one is found. (markt) fix 51794: Fix race condition in NioEndpoint selector. Patch provided by dlord. (fhanik) fix 51905: Fix infinite loop in AprEndpoint shutdown if acceptor unlock fails. Reduce timeout before forcefully closing the socket from 30s to 10s. (kkolinko) fix 52121: Fix possible output corruption when compression is enabled for a connector and the response is flushed. Test case provided by David Marcks. (kkolinko) fix Replace unneeded call that iterated events queue in NioEndpoint.Poller. (kkolinko) fix Improve MimeHeaders.toString(). (kkolinko) fix Allow the BIO HTTP connector to be used with SSL when running under Java 7. (markt) fix Improve multi-byte character handling in all connectors. (rjung) Jasper ------ fix 51220: Correct copy/paste error in original commit for this issue. (markt) fix 52091: Address performance issues related to log creation in TagHandlerPool. Patch provided by Taiki Sugawara. (markt) Cluster ------- add 51736: Make rpcTimeout configurable in BackupManager. (kfujino) add New cluster manager attribute sessionAttributeFilter allows to filter which session attributes are replicated using a regular expression applied to the attribute name. (rjung) fix Avoid an unnecessary session ID change notice. Notice of changed session ID by JvmRouteBinderValve is unnecessary to BackupManager. In BackupManager, change of session ID is replicated by the call of a setId() method. (kfujino) fix Fix unneeded duplicate resetDeltaRequest() call in DeltaSession.setId(String). (kkolinko) add When Context manager does not exist, no context manager message is replied in order to avoid timeout (default 60 sec) of GET_ALL_SESSIONS sync phase. (kfujino) Webapps ------- fix Correct the documentation for the connectionLinger attribute of the HTTP connector. (markt) add Show build date and version in the header on every documentation page. (kkolinko) fix 52049: Improve setup instructions for running as a Windows service: correct information on how a JRE is identified and selected. (markt) update 52172: Clarify Tomcat build instructions. Patch provided by bmargulies. (kkolinko) Other ----- update Update the native component of the APR/native connectors to 1.1.22. (markt) update Update the recommended version of the native component of the APR/native connectors to 1.1.22. (kkolinko) update Update the Eclipse compiler (used for JSPs) to 3.7. (markt) fix Correct two typos in the Windows installer. (kkolinko) fix 52059: In Windows uninstaller: Do not forget to remove Tomcat keys from 32-bit registry on deinstallation. (kkolinko)
2011-12-13Catch up to ocaml changes to enable natdynlink on NetBSD.dholland1-2/+3
2011-12-13fix some low-hanging fruitdholland4-1/+74
2011-12-13This package can't use autoconf as to conflicts with it.sbd5-12/+30
2011-12-13editors/emacs-nox11: Revert previousmarino1-8/+1
emacs-nox11 doesn't use and can't use emacs.desktop, so there is no need to modify the file (which shouldn't even be installed). This modification could go on the editors/emacs port though, conditionally on without x11.
2011-12-13x11/ocaml-graphics: Fix DragonFly PLIST problemmarino1-1/+2
2011-12-13Fix build:dholland1-4/+13
1. "unzip -x file.zip" does not work with any unzip I can find; drop the -x. 2. Because there's a self-extracting archive, NetBSD's builtin unzip doesn't work. When ${OPSYS} is NetBSD, explicitly depend on archivers/unzip instead of adding unzip to USE_TOOLS. (I'm not sure this is the right way to go about this. It at least works though.)
2011-12-13Fix missing $(DESTDIR) on call to mkinstalldirs. Does not fix build,dholland3-10/+30
now has plist issues; not sure what the deal with those is.
2011-12-13Disabling 'Secure' RPC via IMAKEOPTS isn't sufficient -- I thought itdholland3-2/+28
worked at the time, but now it doesn't. Add a BUILDLINK_TRANSFORM hack as well, and now this package builds. (I also just fixed NetBSD HEAD's imake to stop claiming 'Secure' RPC is supported.)
2011-12-13Added devel/p5-Test-CPAN-Meta-YAML version 0.17.hiramatsu1-1/+3
Updated net/p5-Net-CIDR-Lite to 0.21.
2011-12-13Update p5-Net-CIDR-Lite to 0.21.hiramatsu2-7/+7
Changes from previous: ---------------------- 0.21 Wed Mar 28 14:34:18 2007 - Fix RT Tickets: - 14535: Fix spanner clean() docs (reported by carbon at pobox.com). - 25898: Undef dereference with empty object (patch by Adam Tomason). - 30777: Add short_list_range() method (patch by Josef Kutej). - 48308: clean() or list() before add() causes error (reported by David Cawley). - 50042: spanner add() did not accept non-object (patch by Tomo.M). - 52571: "::" not accepted as valid IPv6 address (reported by Tim Wilde).
2011-12-13Add p5-Test-CPAN-Meta-YAML.hiramatsu1-1/+2
2011-12-13Import Test::CPAN::Meta::YAML into devel/p5-Test-CPAN-Meta-YAML,hiramatsu3-0/+35
which is required to update devel/p5-Test-YAML-Meta. This module was written to ensure that a META.yml file, provided with a standard distribution uploaded to CPAN, meets the specifications that slowly being introduced to module uploads, via the use of ExtUtils::MakeMaker, Module::Build and Module::Install.
2011-12-12Fix fallout from newer gnutls.joerg2-1/+16
2011-12-12Avoid double DESTDIR prefixjoerg2-4/+4
2011-12-12Remove duplicate error check from security patch. No revision bump astron2-24/+5
there is no functional change. Problem pointed out by S.P. Zeidler.
2011-12-12Added misc/php-orangehrm version 2.6.11.2ryoon1-1/+2
2011-12-12Add php-orangehrmryoon1-1/+2
2011-12-12Import php*-orangehrm-2.6.11.2 as misc/php-orangehrm.ryoon6-0/+4846
OrangeHRM offers a flexible and easy to use HRIS solution for small and medium sized companies free of charge. By providing modules for personnel information management, employee self service, leave, time & attendance, benefits and recruitment companies are able to manage the crucial organization asset - people. The combination of these modules into one application assures the perfect platform for re-engineering and aligning your HR processes along with the organizational goals.
2011-12-12This isn't a 32-bit program, it's an ordinary program that for some curiousdholland4-8/+23
reason believes that "x86_64" is a 32-bit Intel platform. Fix that, and reenable Dragonfly. While here, add patch comments and include desktopdb.mk. Bump PKGREVISION for the latter.
2011-12-12The DIST_SUBDIR has to be reflected in the distinfo file.dholland2-8/+8
2011-12-12Update homepage, set licenseabs1-3/+4
2011-12-12Updated mail/getmail to 4.24.0schmonz1-1/+2
2011-12-12Update to 4.24.0. From the changelog:schmonz2-6/+6
- add an explicit expunge when closing an IMAP mailbox, for servers that incorrectly do not do this when the mailbox is closed. Thanks: Nicolas Pomarède. - fix incorrect section reference for `mailboxes` parameter in documentation. Thanks: Ross Boylan. - fix getmail_fetch broken in 4.21.0. Thanks: Chris Donoghue.
2011-12-12Updated graphics/py-blockdiag to 1.1.1nb1obache1-1/+2
2011-12-12* apply patch for python<=2.5, taken from upstream.obache6-3/+184
* install manual page. Bump PKGREVISION.
2011-12-12Updated security/opendnssec to 1.3.4pettai1-1/+2
2011-12-12OpenDNSSEC 1.3.4pettai3-8/+10
Bugfixes: * Signer: Use debug instead of warning for drudgers queue being full, also sleep 10 ms if it is full to not hog CPU. This increased signing speed on single core machines by a factor of 2.
2011-12-12Updated comms/asterisk16 to 1.6.2.21jnemeth1-1/+2
2011-12-12Updated comms/asterisk18 to 1.8.7.2jnemeth1-1/+2
2011-12-12graphics/eog-plugins: USE_TOOLS+= msgfmtmarino1-2/+2
2011-12-12games/velena: Mask DragonFly-x86_64marino1-1/+2
DragonFly x86_64 can't build 32-bit binaries.
2011-12-12games/liquidwars: Mask DragonFly64marino1-1/+2
x86_64-DragonFly doesn't have the ability to run or build 32-bit binaries.
2011-12-12games/orbital_eunuchs_sniper: Fix DragonFlymarino1-2/+4
The makefile and PLIST says that x86_64 platforms will produce a file called snipe2d.amd64.dynamic, but on DragonFly the file created was snipe2d.x86_64.dynamic. The Makefile adjusted accordingly.
2011-12-12games/fortunes-futurama: Define DIST_SUBDIR due to tarball repackingmarino1-1/+2
2011-12-12games/fortunes-calvin: define DIST_SUBDIR due to tarball repackingmarino1-1/+2
2011-12-12This update is to fix AST-2011-013 and AST-2011-014.jnemeth2-16/+15
Asterisk Project Security Advisory - AST-2011-013 Product Asterisk Summary Possible remote enumeration of SIP endpoints with differing NAT settings Nature of Advisory Unauthorized data disclosure Susceptibility Remote unauthenticated sessions Severity Minor Exploits Known Yes Reported On 2011-07-18 Reported By Ben Williams Posted On Last Updated On December 7, 2011 Advisory Contact Terry Wilson <twilson at digium.com> CVE Name Description It is possible to enumerate SIP usernames when the general and user/peer NAT settings differ in whether to respond to the port a request is sent from or the port listed for responses in the Via header. In 1.4 and 1.6.2, this would mean if one setting was nat=yes or nat=route and the other was either nat=no or nat=never. In 1.8 and 10, this would mean when one was nat=force_rport or nat=yes and the other was nat=no or nat=comedia. Resolution Handling NAT for SIP over UDP requires the differing behavior introduced by these options. To lessen the frequency of unintended username disclosure, the default NAT setting was changed to always respond to the port from which we received the request-the most commonly used option. Warnings were added on startup to inform administrators of the risks of having a SIP peer configured with a different setting than that of the general setting. The documentation now strongly suggests that peers are no longer configured for NAT individually, but through the global setting in the "general" context. Affected Versions Product Release Series Asterisk Open Source All All versions Corrected In As this is more of an issue with SIP over UDP in general, there is no fix supplied other than documentation on how to avoid the problem. The default NAT setting has been changed to what we believe the most commonly used setting for the respective version in Asterisk 1.4.43, 1.6.2.21, and 1.8.7.2. Links Asterisk Project Security Advisories are posted at http://www.asterisk.org/security This document may be superseded by later versions; if so, the latest version will be posted at http://downloads.digium.com/pub/security/AST-2011-013.pdf and http://downloads.digium.com/pub/security/AST-2011-013.html Revision History Date Editor Revisions Made Asterisk Project Security Advisory - AST-2011-013 Copyright (c) 2011 Digium, Inc. All Rights Reserved. Permission is hereby granted to distribute and publish this advisory in its original, unaltered form. __________________________________________________________________ Asterisk Project Security Advisory - AST-2011-014 Product Asterisk Summary Remote crash possibility with SIP and the "automon" feature enabled Nature of Advisory Remote crash vulnerability in a feature that is disabled by default Susceptibility Remote unauthenticated sessions Severity Moderate Exploits Known Yes Reported On November 2, 2011 Reported By Kristijan Vrban Posted On 2011-11-03 Last Updated On December 7, 2011 Advisory Contact Terry Wilson <twilson at digium.com> CVE Name Description When the "automon" feature is enabled in features.conf, it is possible to send a sequence of SIP requests that cause Asterisk to dereference a NULL pointer and crash. Resolution Applying the referenced patches that check that the pointer is not NULL before accessing it will resolve the issue. The "automon" feature can be disabled in features.conf as a workaround. Affected Versions Product Release Series Asterisk Open Source 1.6.2.x All versions Asterisk Open Source 1.8.x All versions Corrected In Product Release Asterisk Open Source 1.6.2.21, 1.8.7.2 Patches Download URL Revision http://downloads.asterisk.org/pub/security/AST-2011-014-1.6.2.diff 1.6.2.20 http://downloads.asterisk.org/pub/security/AST-2011-014-1.8.diff 1.8.7.1 Links Asterisk Project Security Advisories are posted at http://www.asterisk.org/security This document may be superseded by later versions; if so, the latest version will be posted at http://downloads.digium.com/pub/security/AST-2011-014.pdf and http://downloads.digium.com/pub/security/AST-2011-014.html Revision History Date Editor Revisions Made Asterisk Project Security Advisory - AST-2011-014 Copyright (c) 2011 Digium, Inc. All Rights Reserved. Permission is hereby granted to distribute and publish this advisory in its original, unaltered form.
2011-12-12This needs a pile more tex packages to build successfully in a cleandholland1-1/+18
environment. Note: some of the ones I'm adding may not be absolutely required; I made this list by checking atimes after building R with all tex stuff available, and confirmed that with (only) these packages available it does build. It doesn't help that the R makefile, apparently intentionally, doesn't stop if running tex fails.
2011-12-12This update fixes AST-2011-013 and AST-2011-014. It also adapts to changesjnemeth3-22/+21
in the iLBC codec files. __________________________________________________________________ Asterisk Project Security Advisory - AST-2011-013 Product Asterisk Summary Possible remote enumeration of SIP endpoints with differing NAT settings Nature of Advisory Unauthorized data disclosure Susceptibility Remote unauthenticated sessions Severity Minor Exploits Known Yes Reported On 2011-07-18 Reported By Ben Williams Posted On Last Updated On December 7, 2011 Advisory Contact Terry Wilson <twilson at digium.com> CVE Name Description It is possible to enumerate SIP usernames when the general and user/peer NAT settings differ in whether to respond to the port a request is sent from or the port listed for responses in the Via header. In 1.4 and 1.6.2, this would mean if one setting was nat=yes or nat=route and the other was either nat=no or nat=never. In 1.8 and 10, this would mean when one was nat=force_rport or nat=yes and the other was nat=no or nat=comedia. Resolution Handling NAT for SIP over UDP requires the differing behavior introduced by these options. To lessen the frequency of unintended username disclosure, the default NAT setting was changed to always respond to the port from which we received the request-the most commonly used option. Warnings were added on startup to inform administrators of the risks of having a SIP peer configured with a different setting than that of the general setting. The documentation now strongly suggests that peers are no longer configured for NAT individually, but through the global setting in the "general" context. Affected Versions Product Release Series Asterisk Open Source All All versions Corrected In As this is more of an issue with SIP over UDP in general, there is no fix supplied other than documentation on how to avoid the problem. The default NAT setting has been changed to what we believe the most commonly used setting for the respective version in Asterisk 1.4.43, 1.6.2.21, and 1.8.7.2. Links Asterisk Project Security Advisories are posted at http://www.asterisk.org/security This document may be superseded by later versions; if so, the latest version will be posted at http://downloads.digium.com/pub/security/AST-2011-013.pdf and http://downloads.digium.com/pub/security/AST-2011-013.html Revision History Date Editor Revisions Made Asterisk Project Security Advisory - AST-2011-013 Copyright (c) 2011 Digium, Inc. All Rights Reserved. Permission is hereby granted to distribute and publish this advisory in its original, unaltered form. __________________________________________________________________ Asterisk Project Security Advisory - AST-2011-014 Product Asterisk Summary Remote crash possibility with SIP and the "automon" feature enabled Nature of Advisory Remote crash vulnerability in a feature that is disabled by default Susceptibility Remote unauthenticated sessions Severity Moderate Exploits Known Yes Reported On November 2, 2011 Reported By Kristijan Vrban Posted On 2011-11-03 Last Updated On December 7, 2011 Advisory Contact Terry Wilson <twilson at digium.com> CVE Name Description When the "automon" feature is enabled in features.conf, it is possible to send a sequence of SIP requests that cause Asterisk to dereference a NULL pointer and crash. Resolution Applying the referenced patches that check that the pointer is not NULL before accessing it will resolve the issue. The "automon" feature can be disabled in features.conf as a workaround. Affected Versions Product Release Series Asterisk Open Source 1.6.2.x All versions Asterisk Open Source 1.8.x All versions Corrected In Product Release Asterisk Open Source 1.6.2.21, 1.8.7.2 Patches Download URL Revision http://downloads.asterisk.org/pub/security/AST-2011-014-1.6.2.diff 1.6.2.20 http://downloads.asterisk.org/pub/security/AST-2011-014-1.8.diff 1.8.7.1 Links Asterisk Project Security Advisories are posted at http://www.asterisk.org/security This document may be superseded by later versions; if so, the latest version will be posted at http://downloads.digium.com/pub/security/AST-2011-014.pdf and http://downloads.digium.com/pub/security/AST-2011-014.html Revision History Date Editor Revisions Made Asterisk Project Security Advisory - AST-2011-014 Copyright (c) 2011 Digium, Inc. All Rights Reserved. Permission is hereby granted to distribute and publish this advisory in its original, unaltered form.
2011-12-12sed -i is a gnuism, so make a temporary output file instead.dholland2-5/+6
(Still doesn't build on NetBSD due to C++ issues, though.)
2011-12-12Added devel/p5-POEx-Types version 1.100910.hiramatsu1-1/+3
Updated misc/p5-Vroom to 0.26.
2011-12-12Update p5-Vroom to 0.26.hiramatsu2-7/+6
Changes from previous: ---------------------- version: 0.26 date: Tue Oct 11 21:47:43 EDT 2011 changes: - Add inline script support for running external programs for things like images and browser. - Support for auto-sizing slides (wolfsage++) - Switch from Gloom to Mo. --- version: 0.25 date: Tue Oct 5 22:18:50 PDT 2010 changes: - Use Gloom - Add M:I Makefile.PL stuffs.
2011-12-12Add p5-POEx-Types.hiramatsu1-1/+2